Insight

Breach Under HIPAA May Have Occurred: Am I Required to Notify?

Understanding when a privacy violation rises to the level of a reportable HIPAA breach—and how to evaluate risk under HHS guidance.

Cornell H. Kennedy

Cornell H. Kennedy

December 13, 2024 05:43 PM

Breach Under HIPAA May Have Occurred: Am I Required to Notify?

September 25, 2014 | Sherrard Roe Blog I Cornell H. Kennedy

As you may know, the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) imposes standards for the use and disclosure of protected health information (“PHI”) through its privacy rule (“Privacy Rule”) and imposes standards for the protection of electronic PHI through its security rule (“Security Rule”). As of September 2009, entities covered by HIPAA, including health plans and health care providers (“covered entities”), must notify individuals when their “unsecured” PHI (PHI that is unencrypted) has been breached.

A breach exists if there is an acquisition, access, use, or disclosure of PHI in a manner not permitted by the Privacy Rule, and such action compromises the security or privacy of the PHI.

The Health Information Technology for Economic and Clinical Health Act (“HITECH Act”) includes three exceptions to the definition of “breach,” which include situations where a violation of the Privacy Rule has occurred, but the violation is not to be considered a breach. Those include:

  1. A breach excludes any unintentional acquisition, access or use of PHI by a workforce member (including volunteer or trainee) or person acting under the authority of a covered entity or business associate, if the acquisition, access or use was made in good faith and within the scope of authority and does not result in further use or disclosure in a manner not permitted by the Privacy Rule.
  2. A breach excludes inadvertent disclosures of PHI from a person who is authorized to access PHI at a covered entity or business associate to another person authorized to access PHI at the same covered entity, business associate or organized health care arrangement in which the covered entity participates.
  3. Also exempted are disclosures of PHI where a covered entity or a business associate has a good faith belief that an unauthorized person to whom the disclosure was made would not reasonably have been able to retain such information.

If it is established that the acquisition, access, use or disclosure of PHI violates the Privacy Rule, and that the breach does not meet any of the three regulatory exceptions, a breach is presumed unless, through a risk assessment, the covered entity determines that there is a Low Probability that the data has been Compromised (“LoProCo”). To make this determination, the U.S. Department of Health and Human Services (“HHS”) provides that covered entities and business associates must conduct a risk assessment, taking into consideration, among other things, the following factors:

  1. The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification;
  2. Who was the unauthorized person who received or accessed the PHI;
  3. Whether the PHI was actually acquired or viewed; and
  4. The extent to which the risk to the PHI has been mitigated.

For example, assume that a hospital sends a fax with patient medical information to the wrong fax number outside of the hospital. In performing this analysis, the covered entity should:

  1. Determine whether the PHI – the medical information – identifies the patient, which it is likely it does;
  2. Consider who received the fax. Was it sent to another covered entity that also has confidentiality requirements, which would be viewed as favorable? Or was it sent to a local business that does not have confidentiality requirements?;
  3. Determine whether or not the PHI was actually acquired or viewed or whether there was an opportunity for the PHI to be acquired or viewed. The probability of compromise is lower if only the opportunity existed for the PHI to be acquired or viewed but the PHI was not actually acquired or viewed. However, the covered entity should presumed that the fax was viewed unless further information provides that there was no opportunity to view or acquire the information and;
  4. Mitigate the breach by requesting that the recipient either return or destroy the information.

If the covered entity makes the determination through an in-depth LoProCo analysis that the breach of the PHI does not pose a significant risk of financial, reputational or other harm to the individual, then no breach notification is required. As matter of prudent business practice, the covered entity should always document their risk assessments in order to demonstrate, if necessary, that no breach notification was required.

Trending Articles

2026 Best Lawyers Awards: Recognizing Legal Talent Across the United States


by Jamilla Tabbara

The 2026 editions highlight the top 5% of U.S. attorneys, showcase emerging practice areas and reveal trends shaping the nation’s legal profession.

Map of the United States represented in The Best Lawyers in America 2026 awards

Gun Rights for Convicted Felons? The DOJ Says It's Time.


by Bryan Driscoll

It's more than an administrative reopening of a long-dormant issue; it's a test of how the law reconciles the right to bear arms with protecting the public.

Firearms application behind jail bars

2026 Best Lawyers Awards in Canada: Marking 20 Years of Excellence


by Jamilla Tabbara

Honoring Canada’s most respected lawyers and spotlighting the next generation shaping the future of law.

Shining Canadian map marking the 2026 Best Lawyers awards coverage

Revealing the 2026 Best Lawyers Awards in Germany, France, Switzerland and Austria


by Jamilla Tabbara

These honors underscore the reach of the Best Lawyers network and its focus on top legal talent.

map of Germany, France, Switzerland and Austria

Best Lawyers 2026: Discover the Honorees in Brazil, Mexico, Portugal, South Africa and Spain


by Jamilla Tabbara

A growing international network of recognized legal professionals.

Map highlighting the 2026 Best Lawyers honorees across Brazil, Mexico, Portugal, South Africa and Sp

How to Sue for Defamation: Costs, Process and What to Expect


by Bryan Driscoll

Learn the legal standards, costs and steps involved when you sue for defamation, including the difference between libel and slander.

Group of people holding papers with speech bubbles above them

Build Your Legal Practice with Effective Online Networking


by Jamilla Tabbara

How thoughtful online networking supports sustained legal practice growth.

Abstract web of connected figures symbolizing online networking among legal professionals

Algorithmic Exclusion


by Bryan Driscoll

The Workday lawsuit and the future of AI in hiring.

Workday Lawsuit and the Future of AI in Hiring headline

Blogging for Law Firms: Turning Content into Client Connections


by Jamilla Tabbara

How law firms use blogs to earn trust and win clients.

Lawyer typing blog content on laptop in office

Reddit’s Lawsuit Could Change How Much AI Knows About You


by Justin Smulison

Big AI is battling for its future—your data’s at stake.

Reddit Anthropic Lawsuit headline

How to Choose a Good Lawyer: Tips, Traits and Questions to Ask


by Laurie Villanueva

A Practical Guide for Your First-Time Hiring a Lawyer

Three professional lawyers walking together and discussing work

The 2026 Best Lawyers Awards in Chile, Colombia and Puerto Rico


by Jamilla Tabbara

The region’s most highly regarded lawyers.

Map highlighting Chile, Colombia and Puerto Rico for the 2026 Best Lawyers Awards

Common-Law Marriage in Indiana: Are You Legally Protected?


by Laurie Villanueva

Understanding cohabitation rights and common-law marriage recognition in Indiana.

Married Indiana couple in their home

Why Jack Dorsey and Elon Musk Want to 'Delete All IP Law'


by Bryan Driscoll

This Isn’t Just a Debate Over How to Pay Creators. It’s a Direct Challenge to Legal Infrastructure.

Elon Musk and Jack Dorsey standing together Infront of the X logo

AI Tools for Lawyers: How Smithy AI Solves Key Challenges


by Jamilla Tabbara

Understand the features and benefits within the Best Lawyers Digital Marketing Platform.

Legal professional editing profile content with Smithy AI

Alimony Explained: Who Qualifies, How It Works and What to Expect


by Bryan Driscoll

A practical guide to understanding alimony, from eligibility to enforcement, for anyone navigating divorce

two figures standing on stacks of coins